Two defects the phase 13a walk found by restarting the rig mid-run:
- The watch asked core to reconcile the moment a new boot id appeared, which
is before the game has loaded its save — every crate looked gone and was
orphaned. It now waits for the plugin's hello to say `worldReady`; an older
plugin that never says is taken as ready.
- revert() read any 200 as success. On this bridge a refusal is a 200
carrying world.error (`not-ready` while loading), so every row would have
been marked reverted with the game still holding every crate.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
Core learns which caps an action accepts by pricing its declared examples
once, and drops a dimension priced at zero. A single rust.prefab.place whose
cost moved between rust.prefabs and rust.npcs by its prefab param could only
ever show the crates cap, so D89's separate dial for fights was unreachable.
Two verbs, each pricing exactly one dimension, with the prefab source split
to match (rust.options.crates / rust.options.npcs). The switchboard can now
allow crates and leave NPCs off. The plugin's world.place is unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
- registerEventActions: rust.zone.open and rust.prefab.place, both
reversible 'ledger' with revert() and reconcile(), budgetMs 15000 above the
client's 12 s. A location is a monument (kind + instance, carrying its
server) or raw coordinates, exactly one (D87, D93); bounds mirrored from the
plugin so a bad step is refused on the form (D95); zone minutes required and
held by the game (D96).
- registerEventBudgets: rust.prefabs, rust.npcs and rust.zone.minutes, each
beside the verb that spends it (D79, D89).
- Option sources rust.options.monuments (live, searchable) and
rust.options.prefabs (mirrored, answers with every server off), registered in
the one batch core accepts alongside the lease sources.
- Refs are <serverId>:<id>, since revert and reconcile get no params. The undo
sends no idempotency key; a lost answer is reverted by key on every server.
reconcile asks the plugin, and a server that cannot be asked keeps its rows.
- The refresh's bootId/wipeId watch calls ctx.events.reconcile() on a restart
or a wipe, never on a first sighting or a reconnect (§11.1).
- The permission mirror keeps the plugin's new notLanded grants out of what it
records as pushed, and the admin page says so (D85).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY